EU finalizes landmark law to regulate 'high-risk' AI systems

A vew of the EU Telecommunications and Energy Council meeting. The Ministers address recently adopted legislation in the digital field and the future of the EU's digital policy on the future of cybersecurity. -/European Council/dpa

EU ministers have unanimously given their final approval to the Artificial Intelligence Act, a major new law that regulates the use of the transformative technology in "high-risk" situations, such as law enforcement and employment.

The European Union hopes that by laying down strict AI rules relatively early in the technology's development it will address the dangers in time and help shape the international agenda for regulating AI.

Systems intended for use in "high-risk" situations, which are listed in the law's annexes, will have to meet various standards spanning transparency, accuracy, cybersecurity and quality of training data, among other things. Some uses - such as Chinese-style social credit scoring - will be banned outright.

High-risk systems will have to obtain certification from approved bodies before they can be put on the EU market. A new "AI Office" will oversee enforcement at EU level.

There are also more basic rules for "general purpose" systems that may be used in various situations - some high-risk, others not. For example, providers of such systems will have to keep certain technical documents for audit.

But providers of especially powerful general purpose AI systems will have to notify the European Commission if the system possesses certain technical capabilities.

Unless the provider can prove that their system poses no serious risk, the commission could designate it as a "general-purpose AI model with systemic risk," after which stricter risk-mitigation rules would apply.

Meanwhile, AI-generated content such as images, sound or text would have to be marked as such to protect against misleading deepfakes.

The European Commission proposed the first draft of the AI Act in April 2021, having published a "white paper" outlining its plan for a risk-based approach in February 2020.

The European Parliament pushed for much stricter rules - such as a blanket ban on police use of real-time facial recognition in live CCTV feeds.

But EU member states were reluctant to impose too many restrictions on law enforcement and border security, and feared too much red tape would harm economic competitiveness.

Negotiators for the parliament and the member state finally reached a compromise in December, after several rounds of gruelling late-night talks.

The final law does impose a general ban on real-time facial recognition in CCTV, but there are exceptions for law enforcement uses, such as finding missing persons or victims of kidnapping, preventing human trafficking, or finding suspects in serious criminal cases.

Now that the law had been finalized by today's unanimous vote among ministers, it must be signed by the presidents of the EU legislature and then published in the EU's statute book. It then technically becomes law 20 days later, but most of its provisions won't take effect until two years after that.